PatchSiren cyber security CVE debrief
CVE-2026-108623 jeecgboot CVE debrief
CVE-2026-108623 is a missing authorization vulnerability in JeecgBoot through 3.9.5, specifically in the SysLogController deleteBatch handler. This allows any authenticated user to delete system audit log entries. Low-privileged attackers can exploit this by sending a DELETE request with ids set to 'allclear' to wipe the entire sys_log table, effectively erasing all users' audit trails.
- Vendor
- jeecgboot
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
System administrators, security teams, and developers using JeecgBoot should assess their exposure and implement necessary mitigations. This vulnerability is particularly concerning for systems where audit logs are critical for security, compliance, or forensic analysis.
Why it matters
CVE-2026-108623 is a high-severity vulnerability in JeecgBoot that allows authenticated users to delete system audit logs without authorization. This can lead to loss of critical audit trails, making it difficult to detect and respond to security incidents. Defenders should prioritize verifying and mitigating this vulnerability, especially in systems where audit logs are critical for security and compliance.
- Loss of audit trail for security and compliance purposes.
- Potential for undetectable malicious activity due to deleted logs.
- Increased risk of insider threats or unauthorized actions without accountability.
- Difficulty in forensic analysis due to missing log data.
Technical summary
The vulnerability exists in the SysLogController deleteBatch handler of JeecgBoot through 3.9.5. This handler allows any authenticated user to delete system audit log entries without proper authorization. An attacker can exploit this by sending a DELETE request with ids set to 'allclear' to delete all log entries, effectively erasing audit trails. Defenders should prioritize verifying and mitigating this vulnerability, especially in systems where audit logs are critical for security and compliance. The vulnerability has a high severity score of 7.1 and is considered a high-severity issue.
Defensive priority
Defenders should prioritize verifying and mitigating this vulnerability, especially in systems where audit logs are critical for security and compliance.
Recommended defensive actions
- Verify the version of JeecgBoot being used and check if it's within the affected range.
- Implement proper authorization checks for the SysLogController deleteBatch handler.
- Restrict access to the SysLogController deleteBatch handler to only authorized users.
- Monitor system audit logs for any suspicious deletion activities.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability in JeecgBoot through 3.9.5. The vulnerability exists in the SysLogController deleteBatch handler, allowing any authenticated user to delete system audit log entries without proper authorization. Defenders should verify the affected versions, implement proper authorization checks, and monitor system audit logs for suspicious deletion activities. Evidence is limited to CVE and NVD details; further verification is needed to confirm affected scope and remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108623 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108623
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108623 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108623
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_log_delete_batch.py
-
Source reference
Unverified legacy reference
URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysLogController.java
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sys-log-deletebatch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.